It is in some comments related to running in mixed mode, but our net is
running AD in native mode. Further it seems to occure on all DC-s in the
domain, and there is 4 to 5 incidents roughly every 15 minutes, even in the
midle of the night, when no logon is supposed to go on.
In the last five days, there also have been 8 Success Audit, saying:
Kerberos Policy Changed:
Changed By:
User Name: VVS-SRV-10$
Domain Name: DOMAIN
Logon ID: (0x0,0x3E7)
Changes made:
('--' means no changes, otherwise each change is shown as:
<ParameterName>: <new value> (<old value>))
--
Could there be a connection?
--
MJOlsen